ATT&CKReferencesUnit 42 IronNetInjector February 2021

Unit 42 IronNetInjector February 2021

Reichel, D. (2021, February 19). IronNetInjector: Turla’s New Malware Loading Tool. Retrieved February 24, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
ToolIronNetInjector

IronNetInjector can obfuscate variable names, encrypt strings, as well as base64 encode and Rijndael encrypt payloads.

T1036.004
Masquerade Task or Service
ToolIronNetInjector

IronNetInjector has been disguised as a legitimate service using the name PythonUpdateSrvc.

T1053.005
Scheduled Task
ToolIronNetInjector

IronNetInjector has used a task XML file named mssch.xml to run an IronPython script when a user logs in or when specific system events are created.

T1055
Process Injection
ToolIronNetInjector

IronNetInjector can use an IronPython scripts to load a .NET injector to inject a payload into its own or a remote process.

T1055.001
Dynamic-link Library Injection
ToolIronNetInjector

IronNetInjector has the ability to inject a DLL into running processes, including the IronNetInjector DLL into explorer.exe.

T1057
Process Discovery
ToolIronNetInjector

IronNetInjector can identify processes via C# methods such as GetProcessesByName and running Tasklist with the Python os.popen function.

T1059.006
Python
ToolIronNetInjector

IronNetInjector can use IronPython scripts to load payloads with the help of a .NET injector.

T1059.006
Python
GroupTurla

Turla has used IronPython scripts as part of the IronNetInjector toolchain to drop payloads.

T1140
Deobfuscate/Decode Files or Information
ToolIronNetInjector

IronNetInjector has the ability to decrypt embedded .NET and PE payloads.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.